Data & Privacy

How Nudgg protects behavioral data.

What gets filtered before capture, what your team can control, and why every AI-prepared action stays reviewable before it reaches a customer.

Sensitive data protection

Designed to keep sensitive data out.

High-risk inputs are filtered before they become usable signals.

Privacy filter

Filters before capture

Excludes sensitive data

Collection controls

Control what gets captured.

Decide what Nudgg should capture, ignore, or reinterpret.

Capture policyActive
Password & payment fieldsExcluded
Custom event namesMapped
Marked-private elementsIgnored

Human approval

Human approval, always.

Nudgg prepares the action. Your team decides what goes live.

AI preparesDraft
ReviewRequired
ApprovedManual
Nothing launches automatically

Governed AI

See why Nudgg recommends it.

See the signals and confidence behind each suggestion before you act.

Evidence

Behavioral signals

Journey activity

Recent changes

Recommendation

91%

Checkout recovery audience

~1.2k users

Ready for review

Data capture

What's captured, what isn't.

The same rules the SDK itself enforces — not a separate policy layered on top.

Auto-captured
  • site_visit
  • page_view
  • SPA route changes (pushState, replaceState, popstate, hashchange)
  • Allowed UTM / ad-attribution query parameters
  • Safe page, session, and browser context
Only when enabled
  • Click metadata, once a workspace admin turns it on
  • Safe clickable element label
  • Element tag and role
  • Click coordinates
  • Page context
Never captured
  • Password values
  • OTP values
  • Payment, card, and CVV values
  • Input, textarea, and select values
  • Full page text
  • Non-allowlisted query parameters
  • Content inside private / no-track regions

Collection controls

Exclude anything, structurally.

Mark a region private and Nudgg never captures clicks inside it — not later, at the source.

data-privatedata-no-trackdata-nudgg-privatedata-nudgg-no-track
  • Clicks inside private regions are not auto-captured.
  • For checkout, payment, login, and support flows, mark the full section private.
  • Send an explicit, safe custom event with track() instead.

Governed AI

Built to stay accurate, not just polite.

Growth agents can draft copy. They cannot invent targeting, mechanics, or numbers that aren't already in your data.

01

Nudgg does not store raw visitor IP addresses in behavioral event data — location stays approximate by design.

02

AI can write campaign copy. It never decides who a campaign targets or how it fires — that stays backend-owned, every time.

03

AI-suggested copy is checked against real evidence before it's ever shown to your team — unsupported claims get rejected, not published.

04

Every campaign a growth agent proposes starts as a draft. Nothing goes active until your team reviews and launches it.

Consent

Consent, built channel by channel.

On-site is a first-party experience on your own product. Anything that leaves your product to reach a customer directly carries its own consent check.

WhatsApp — in testing

Every send is checked against recorded consent before it goes out, and an opt-out is honored on the very next send. SMS, RCS, and email are planned next, on the same consent model.